Junglewise Threat Intelligence

CVE-2026-57028: Juniper Networks Junos OS Evolved license exhaustion via open port

CVE-2026-57028 · Severity: high · CVSS 7.3 · Published 2026-07-09

Technologies: Juniper Networks Junos OS Evolved. Vendors: Juniper Networks.

Executive brief

A vulnerability in Juniper Networks Junos OS Evolved allows unauthorized users to access internal license management functions over the network. This could allow an attacker to exhaust available device licenses, potentially disrupting service or preventing legitimate license activation. The issue stems from a process that should be restricted to internal communication being exposed on an open network port.

Technical details

An Improper Restriction of Communication Channel to Intended Endpoints (CWE-923) vulnerability exists in Juniper Networks Junos OS Evolved due to incorrect initialization. This flaw causes a process intended only for internal device communication to be reachable over the network via an open port. An unauthenticated attacker can exploit this to gain unauthorized access to license management functions, leading to license exhaustion. The issue affects all versions prior to 23.2R2-EVO.

Affected products

  • Juniper Networks Junos OS Evolved All versions before 23.2R2-EVO

Timeline

  • 2026-07-09: advisory: Initial advisory published by Juniper Networks

References

Related threats